The Data You Didn't Mean to Share
When office administrator Sara forwards a simple spreadsheet to a colleague, she unknowingly triggers a serious GDPR violation — and discovers how easy it is to mishandle personal data without even realizing it. This scenario walks beginners through core data privacy obligations in an everyday workplace setting.
When office administrator Sara forwards a simple spreadsheet to a colleague, she unknowingly triggers a serious GDPR violation — and discovers how easy it is to mishandle personal data without even realizing it. This scenario walks beginners through core data privacy obligations in an everyday workplace setting.
It was a Tuesday morning, unremarkable in every way. Sara Malik, an office administrator at a mid-sized logistics company in Birmingham, had just finished her second coffee when her manager, David, leaned over from the neighboring desk.
"Sara, can you send the staff contact list over to Priya in HR? She needs it for the team-building event invitations."
Sara nodded, opened her email, and searched for the last version of the list she remembered sending months ago. She found it quickly — a spreadsheet titled Staff_Contacts_FULL_v3.xlsx. Without opening it to check the contents, she forwarded it to Priya and went back to her morning tasks.
Simple. Done. Or so she thought.
Twenty minutes later, Priya appeared at Sara's desk, looking uncertain.
"Sara… this spreadsheet has a lot more than names and emails. It has employee home addresses, dates of birth, national insurance numbers, salary bands, and medical notes from HR reviews. I only needed first names and work emails. Did you mean to send all of this?"
Sara's stomach dropped. She pulled up the file. Priya was right. Somehow, over months of updates, the "contact list" had evolved into something far more sensitive — a full employee data register. Sara had sent the personal details of 47 employees to someone who only had a legitimate need for two data fields.
This wasn't malicious. It wasn't a hack. It was a quiet, accidental violation of the General Data Protection Regulation (GDPR) — and it had happened in under sixty seconds.
Sara immediately told her manager, David, who looked serious. "We need to report this to the Data Protection Officer," he said. "Under GDPR, we have 72 hours to assess whether this needs to be reported to the ICO. Don't delete anything — we need to document exactly what happened."
The company's Data Protection Officer, a calm and methodical woman named Janet, walked Sara through what had gone wrong. The core issue wasn't bad intention — it was a failure to apply the principle of data minimisation: only sharing the minimum personal data necessary for a specific, legitimate purpose.
"GDPR isn't just about hackers and data breaches," Janet explained patiently. "It applies every time you handle someone's personal information — when you email it, store it, print it, or share it. Every employee whose data was in that spreadsheet has rights. They have the right to know how their information is being used, and the right to expect it will be protected."
Sara learned that personal data includes far more than most people assume: names combined with addresses, health information, financial details, ID numbers — all of it is protected under GDPR. And the responsibility for protecting it doesn't rest only with the IT department. Every employee who handles data is a data handler, with real legal and ethical obligations.
Janet also flagged a second problem: the spreadsheet had been sitting in Sara's email inbox — unsecured, unlabelled, and accessible to anyone who might have had access to her account. Sensitive files containing personal data should be stored in secure, access-controlled systems, not floating around in email threads.
Fortunately, because Priya had flagged it immediately and no data had been passed on further, the incident was contained. After a thorough internal assessment, the company determined it did not meet the threshold for mandatory ICO reporting — but it was still logged as an internal near-miss, and Sara was required to complete refresher data protection training.
That afternoon, Sara sat quietly at her desk. She thought about the 47 colleagues whose home addresses, medical notes, and salary information had briefly landed somewhere they shouldn't have. They had no idea it had happened. They had trusted the company — and by extension, people like Sara — to handle their private information with care.
She resolved never to forward a file without opening it first, never to share more data than was asked for, and never to assume that "it's just an internal email" made something safe.
Data privacy, she understood now, wasn't a technical problem. It was a habit — one she intended to build, one careful decision at a time.
- Apply data minimisation: Only share the minimum personal data necessary for the specific task at hand. Always ask yourself — does this person actually need all of this information?
- Check before you send: Always open and review a file before forwarding it. File names can be misleading, and contents evolve over time without obvious labels changing.
- Understand what "personal data" means: Under GDPR, personal data includes names, addresses, dates of birth, health information, financial data, and ID numbers — not just passwords or banking details.
- Every employee is a data handler: Data protection is not just the IT or legal team's responsibility. Anyone who reads, sends, stores, or prints personal information has obligations under GDPR.
- Report incidents quickly: If you suspect a data breach or accidental disclosure, report it to your Data Protection Officer immediately. GDPR requires organisations to assess incidents within 72 hours.
- Store data securely: Sensitive personal data should be kept in secure, access-controlled systems — not in unlabelled email attachments or shared folders without proper permissions.
Unlock This Scenario & Quiz
The Free plan includes 3 scenarios. Upgrade for full access to every scenario and quiz.
⬆️ View Plans